IP Library Granted Patent US 12683799
Granted Patent B2
US 12683799 · App. 18/808,983 · Granted Jul 14, 2026

Detection of unauthorized cryptomining

Inventors: Dylan Reid (Atlanta, GA); Joseph Soryal (Ridgewood, NY)
Assignee: AT&T Intellectual Property I, L.P.
H04L9/3239H04L9/0643H04L9/0819H04L9/088H04L43/0876H04L45/125H04L47/72H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12683799
App. No.
18/808,983
Granted
Jul 14, 2026
Kind
B2
Abstract

A processing system of a device having at least one processor may determine that a temperature of the device exceeds a threshold temperature and obtain, in response to the determining, utilization information of the device comprising: processor utilization information, memory utilization information, and network utilization information. The processing system may then detect, from the utilization information of the device, a pattern comprising: a first network utilization burst, a processor utilization exceeding a processor utilization threshold and a memory utilization exceeding a memory utilization threshold over at least a designated period of time following the first network utilization burst, and a second network utilization burst after at least the designated period of time. When the pattern is detected, the processing system may generate an unauthorized cryptomining alert.

Claims (38)

1 . A method comprising:

obtaining, by a processing system of a device, utilization information of the device comprising: processor utilization information, memory utilization information, and network utilization information;

determining, by the processing system, from the processor utilization information and the memory utilization information, that an overall processor utilization of the device is in excess of an overall processor utilization threshold, and that an overall memory utilization of the device is in excess of an overall memory utilization threshold;

detecting, by the processing system in response to the determining, from the utilization information of the device, a pattern comprising: a first network utilization burst, a processor utilization exceeding a processor utilization threshold, and a memory utilization exceeding a memory utilization threshold over at least a designated period of time following the first network utilization burst, and a second network utilization burst after at least the designated period of time, wherein the pattern is detected for a process that is running on the device;

in response to the detecting the pattern, detecting a performance of at least one designated action by the process that is indicative of unauthorized cryptomining, wherein the at least one designated action comprises at least one of:

a number of hashing operations of the process that are in excess of a threshold number of hashing operations within the designated time period;

a performance of at least one operation with respect to a distributed ledger;

a request to reserve processor resources of the device in excess of a processor resource reservation threshold;

a request to reserve memory resources of the device in excess of a memory resource reservation threshold; or

a key exchange with a remote device within the first network utilization burst; and

generating, by the processing system, an unauthorized cryptomining alert in response to the detecting the pattern.

2 . The method of claim 1 , wherein the pattern further comprises an absence of an input for the process within the designated period of time.

3 . The method of claim 1 , wherein the generating of the unauthorized cryptomining alert is in accordance with the detecting of the at least one designated action.

4 . The method of claim 1 , further comprising:

transmitting the unauthorized cryptomining alert to at least one monitoring device.

5 . The method of claim 1 , further comprising:

determining, by the processing system, an electricity utilization of the device is in excess of an electricity utilization threshold, wherein the electricity utilization threshold is set based upon historical electricity utilization measurements of the device over a period of time.

6 . The method of claim 1 , further comprising:

determining, by the processing system, an electricity utilization of the device is in excess of an electricity utilization threshold, wherein the electricity utilization threshold is set based upon historical electricity utilization measurements of a plurality of devices of a same device type as the device over a period of time.

7 . The method of claim 1 , wherein the processor utilization threshold is set based upon historical utilization information comprising historical processor utilization measurements of the device, and the memory utilization threshold is set based upon the historical utilization information comprising historical memory utilization measurements of the device.

8 . The method of claim 7 , wherein the processor utilization threshold and the memory utilization threshold are determined in accordance with at least one machine learning model that is trained over the historical utilization information of the device.

9 . The method of claim 5 , wherein the determining the electricity utilization of the device is in excess of an electricity utilization threshold comprises monitoring the electricity utilization of the device during an after-hours time period of the device.

10 . The method of claim 1 , wherein the designated period of time comprises at least 5 minutes.

11 . The method of claim 10 , wherein the designated period of time comprises at least 10 minutes.

12 . The method of claim 1 , wherein the designated period of time is learned by the processing system via a machine learning model.

13 . The method of claim 1 , wherein the overall processor utilization threshold and the overall memory utilization threshold are determined in accordance with a machine learning model that is trained over historical utilization information of the device.

14 . The method of claim 9 , wherein the after-hours time period is defined by an operator of the device.

15 . A method comprising:

obtaining, by a processing system of a device, utilization information of the device comprising: processor utilization information, memory utilization information, and network utilization information;

determining, by the processing system, from the processor utilization information and the memory utilization information, that an overall processor utilization of the device is in excess of an overall processor utilization threshold, and that an overall memory utilization of the device is in excess of an overall memory utilization threshold;

detecting, by the processing system in response to the determining, from the utilization information of the device, a pattern comprising: a first network utilization burst, a processor utilization exceeding a processor utilization threshold, and a memory utilization exceeding a memory utilization threshold over at least a designated period of time following the first network utilization burst, and a second network utilization burst after at least the designated period of time;

generating, by the processing system, an unauthorized cryptomining alert in response to the detecting the pattern; and

transmitting the unauthorized cryptomining alert to at least one monitoring device, wherein the unauthorized cryptomining alert is transmitted to a plurality of monitoring devices, and wherein responses from at least two of the plurality of monitoring devices are required to deactivate the unauthorized cryptomining alert.

16 . A method comprising:

obtaining, by a processing system of a device, utilization information of the device comprising: processor utilization information, memory utilization information, and network utilization information;

determining, by the processing system, from the processor utilization information and the memory utilization information, that an overall processor utilization of the device is in excess of an overall processor utilization threshold, and that an overall memory utilization of the device is in excess of an overall memory utilization threshold;

detecting, by the processing system in response to the determining, from the utilization information of the device, a pattern comprising: a first network utilization burst, a processor utilization exceeding a processor utilization threshold, and a memory utilization exceeding a memory utilization threshold over at least a designated period of time following the first network utilization burst, and a second network utilization burst after at least the designated period of time, wherein the processor utilization threshold is set based upon historical utilization information comprising historical processor utilization measurements of the device, and the memory utilization threshold is set based upon the historical utilization information comprising historical memory utilization measurements of the device, and wherein the processor utilization threshold is set further based upon historical processor utilization measurements of additional devices of a same device type as the device, and the memory utilization threshold is set based upon historical memory utilization measurements of the additional devices; and

generating, by the processing system, an unauthorized cryptomining alert in response to the detecting the pattern.